My TVs are on the IoT network so that I can control them from Home Assistant, but they're blocked from accessing the internet.
DNS lookups are redirected or blocked (53 redirected to my local DNS resolver, 853 blocked), and DoH is blocked as best effort though it's hard to block HTTP DNS traffic, which again is why the devices are blocked in the firewall.
All streaming is done via AppleTV, which is a platform I trust infinitely more than LG/Samsung/whatever.
All of your blocking still doesn't change the fact that your LG TV is actively trying to scan your local hardware, gathering IP-addresses of devices, wi-fi names and signal strengths, creating digital finger prints of the audio and video projected on your screen, recording audio through the internal microphone, even when the TV is in standby or without an internet connection, saving the collected data locally and uploading to LG Ad Solutions as soon as the TV is connected to the internet.
Yeah which is why its imperative that you _never_ connect to the Internet.
More imperative is that you _never_ buy one.
[dead]
But it's never connected to the internet, not even for software updates. If the TV isn't connected to the internet there's no reason to update it, assuming the TV works as expected.
It's a trade off I guess. I use Home Assistant to control TVs, so kinda need the access.
Have you noticed that on many home routers there is now a default open, sometimes password protective network named AT&T or Cox Wi-Fi? That’s the backhaul. The TV will join that automatically without asking you because they have an agreement with the network provider. This is how tons of devices phone home now. You don’t ever need to add a device on your network for it to have internet. If there’s a partner Wi-Fi network anywhere, it’ll push through that.
They tried that in Denmark a decade ago (or more). Enabled a "public wifi" on all home routers to provide wifi coverage for that company's customers everywhere.
They gave every assurance that it would be secure, completely separate from the users own network, and the bandwidth consumed would be added on top of whatever the user had a contract for.
It took a couple of days after launch before somebody managed to gain access to someone's private network from the public network and they shut it down again and never opened it again.
Anyway, I may be spoiled from living in Denmark, but I'm using my own router, which is an option when ordering, so I'm fairly certain nobody is sharing additional wifi hotspots.
And it's not just me. The majority of people I know use some kind of 3rd party router with their ISP. Granted, some of them just use whatever the ISP sends them, but even then I haven't ever seen any additional wifi networks, and the ISP prints the router admin password on the box itself, so you can poke around if you like (though the ISP has a backdoor, which is also why 3rd party routers are a thing).
The TV will join that automatically without asking you because they have an agreement with the network provider.
This seems far fetched to me. Have you seen evidence or reliable reporting of this?
Why is this more far fetched than LG smart TVs recording audio while pretending to be off and caching the results waiting for an opportunity to exfiltrate the precious data? We're in a "if they can they will" world with this stuff.
Comcast sets up a secondary wifi network on their routers in your home that they use as the backhaul for smartphones. Why wouldn't they make a deal with LG or whoever to use that data? We've already established they'll do about a half-a-Stuxnet to get at this data, you're telling me they won't do a couple bulk deals with common ISPs?
Why go through all that trouble of spoofing MAC addresses or assuming it will always be able to connect to an open WiFi network.
5G connectivity is cheap. You can put a 5G modem in pretty much any device for $10 or less, and pay roughly $2/year in subscription fees. My local water utility with ~900 subscribers pays $2/year for 5G connectivity for water meters, and I have no doubt you can get it much cheaper at scale.
They don't even have to tell you about the 5G modem. It could exclusively be used for exfiltrating data about your viewing habits. It's virtually undetectable and more or less impossible to block. The TV could behave nice on the Wifi, you can block all the DNS servers you like, it would still be able to phone home.
because using open wifi is infinity cheaper.
You are asking for $20 increase in BOM, which means they somehow has to extract $20 from your private data, which is hard.
Or simply increase the selling price by $20, would you even notice ?
And if they're not expecting to make $20 over 10 years selling your data, it hardly seems worth risking your reputation over.
It’s just the BOM price. When your product has Cellular module, there is set of certification that is painful to pass. It’s better to use included wifi module since it’s already there and certified
Okay, even if you don’t agree with me that it’s far fetched, claims of ‘X is doing Y’ usually require some evidence that X is doing Y to be considered credible.
after everything we’ve seen factually that companies do, why would this, of all things, seem far-fetched to you?
i think it would be significantly more far-fetched that cable companies don’t sell them access. i would be shocked if they didn’t.
How about this? LG builds many other home appliances like washers and driers. Some have apps and wifi.
Why wouldn’t LG allow their devices to talk to each other locally, without needing to join a network? With private SSID or something like that? Only one appliance would need internet access.
This shit already exists. Like Amazon Sidewalk: https://ring.com/amazon-sidewalk
Now, I’m not saying LG is doing it, but this is not a far fetched technical concept. The only reason they’re potentially not going that far is because most people probably just connect it to the internet so why bother about the few who don’t.
The devices are already scanning the network for any devices and software they can find, and mapping your phone to your TV viewing habits for example. The LG execs are on record bragging about it. So I don’t see why it’s absurd
This is alarmingly realistic to me.
The part about ISP routers broadcasting an alternate "hotspot" SSID is documented [1] and can be easily observed. Walk around any city, open your phone's wifi settings and see networks like "xfinitywifi" or "optimumwifi". As an end user, if you connect to one of these networks from your device, you'll get a captive portal web page that makes you sign in to your ISP account. Once signed in, you get internet access courtesy of the router sitting in whatever home or business you happen to be near to.
In addition to ISPs allowing their own subscribers access, there are examples of corporations cutting deals with ISPs for hotspot network access. For example, Google's MVNO Google Fi has a deal with unnamed partners that allows subscribers' phones to connect to hotspot wifi networks for extra coverage, branded "Wi-Fi Auto Connect+" [2].
From the user's perspective (and personal experience), this connection is handled seamlessly and outside of the OS' normal wifi UI flow. If your phone sees no saved wifi networks but does see xfinitywifi (et al), it auto-connects in the background. Authentication with the captive portal happens automatically and non-interactively, presumably with some keys provisioned to your device. Your traffic is VPNed back to Google, so the router and ISP don't see anything. The only indication that any of this happened is that the "5G" icon changes to "W+"; the normal WiFi icon never shows up.
In the case of Google Fi, this is actually a pretty great deal for users. You get better coverage (especially indoors in cities, where cell service can be spotty) with no real downsides to you – your traffic isn't meaningfully exposed to another third party, it doesn't cost you extra, and you don't have to bother the staff for a wifi password.
But given all that, it's not a huge leap to believe that ISPs are also more than willing to quietly take LG's money in exchange for an all-access pass to their hotspot network.
It's easy to imagine that an evil company could ship their TV with a key that allows it on an ISP's hotspot network. No extra suspicious hardware like a 5G modem needed, and no MAC address spoofing required. The TV software could easily connect to the hotspot network with zero indication in the UI, and then use the surreptitious connection only to transmit your kompromat back to HQ.
If done intelligently, you'd never notice. By only transmitting spy reports (and not downloading new ads), even a keen observer wouldn't notice any behavior on the TV that would trigger "how tf did this thing get a network connection?" Even more insidious, you couldn't really see what traffic was happening, since IP packet captures on your network are useless in this scenario. You'd need special hardware to capture what the TV is actually doing on the air.
If truly evil, the software could do this hotspot dance even if you've configured your own WiFi network on the TV. If the software finds it can't reach ad HQ because you've firewalled it off, then despite your best efforts to contain the disease, it still can spy effectively thanks to your neighbor's router with its default-enabled ISP hotspot. Just do a daily upload while you're sleeping and otherwise sit innocuously on your locked-down VLAN.
Everyone evil wins: ISP collects that sweet bonus revenue at zero marginal cost, TV manufacturer doesn't have to foot the hardware bill for millions of 5G modems or (relatively) expensive cellular agreements, and advertisers get to be that much more creepy targeting you. I'm sure the wanna-be despots of the world don't mind the spy apparatus being built for them either, conveniently under the control of easily-compelled corporations.
--
Now to be clear, I have no proof that any TV manufacturer is surreptitiously connecting to an ISP's hotspot network in order to exfiltrate your data. But all of the building blocks to make that happen provably do exist, and I seriously doubt that capitalism will allow them to go unused.
It's anything but far-fetched.
[1] eg https://www.xfinity.com/support/articles/xfinity-wifi-hotspo... and https://www.spectrum.net/support/internet/spectrum-mobile-wi... and https://www.optimum.net/pages/internet/hotspots/faq.html
[2] https://fi.google.com/about/wi-fi-auto-connect-plus and https://support.google.com/fi/answer/10091529?hl=en
Joining that network from a new device always presents a captive portal that requires the credentials of my ISP account, so how does that work for you?
Where is a web link indicating partnerships, and compatible hardware lists? My ISP does not sell any TV sets.
which home router?
Again, what I mean is, even if you're able to block all these things, the company LG is still secretly and actively trying to collect and process user data, without user awareness or consent.
Actually what I wanted from the video was impact of user consent, but it doesn't seme to cover this: what happens if you accept nothing, or the minimal set of consent (so not including audio) of licenses to allow you to run third-party apps? I recall there are four checkboxes to check.
My guess is: not much.
What if you sell the TV? Can you clear the data with a factory reset so it's not just uploaded when a new user connects it?
LG has a cereal port on most of their televisions and monitors. There are quirks and bugs in some models but the general packet structure is simple and it's pretty straightforward to get an ESP32 with ESP home talking to the monitor.
Do transparent faraday cages exist?
WiFi / 5G faraday cages exist, but they have been downrated for affecting the signal quality somewhat...
And then your neighbor spins up an unprotected network or something like xfinity which they could have a deal with and it connects there and phones home anyways.
I hear this a lot “TVs will just connect to a nearby unprotected WiFi network!” But I ve never seen any evidence of it. It appears to just be speculation, unless you have an actual source?
Its always speculation that would be trivial to actually test.
1. Do not connect to network 2. Create unauthenticated WiFi network 3. Monitor WiFi network
Strange no one has ever done this simple af test to backup their claims
If TV manufacturers wanted to be underhanded then they could actually make this much harder to detect by delaying the connection to new unauthenticated networks for e.g. months or only after seeing another device connect and then using that device's MAC when it is not around.
Still super easily detectable even if they clone a MAC.
I have an unprotected guest network with a captive portal and an LG C1. I have never seen the LG pop up in the logs for the guest network.
Because they don't. It's too much guesswork, and honestly pretty complicated. From the user perspective the TV would appear to go offline every now and then, so also somewhat easily detected.
It's much easier to just throw a $10 5G modem in there, pay the $2/year subscription fee for service, and extract data that way. Assuming a 5-10 year relevant lifespan of the TV, they'd throw $20-$30 on top of the sales price for the modem and 10 years of service.
The 5G modem could run completely independent of the wifi network, be a completely different circuit, and you'd never know it was there.
Except they don’t do that either. I’m not aware of any TV that bundles a 5G modem. Are you?
almost all new cars have cellular modems reporting all kinds of shit, something like over 90% of new cars. what makes you think tv companies aren’t?
even the ones that aren’t yet, we’d be incredibly incredibly naive to think it’s not on their radar.
Cars having 5G connectivity is something that consumers actually want, it’s well documented on the spec sheets and marketing material, and obviously in a car WiFi is not going to work in most places. None of those things apply to TVs.
For one, you can take apart your TV and see that it doesn't have a SIM card
Can you spot a device like this : https://www.intersign.dk/cdn/shop/products/868e2a0dce897d05a...
The linked image shows a module meant for easy integration, but it could also simply be a part of the main board of the TV. They could "hide" the GSM antenna alongside the wifi antenna.
They could also use something like Amazon Sidewalk or ATSC 3.0's dedicated return channel.
They could (although I’m not sure of the 80Kbps that Amazon sidewalk allows is really sufficient for the purpose of uploading ACR data), but is there any evidence that any TV manufacturer actually is? The reality is, why would they bother? 95% percent of people that buy a “Smart TV” hook it right up to their WiFi as soon as they take it out of the box.
80Kbps is enough, after all they don't want to accidentally ddos their server.
ACR isn't generally a lossless 4K snap shot but indexed 32x32 pixel blocks from arbitrary locations on screen. In some cases it's even a fuzzy hash of the content source, and while 80Kbps isn't a lot, you can still push out data in a timely manner.
Seeing how things have recently been developing, I'd bet on it already being the case or at least in active development.
If you think its already the case, how come nobody can provide any evidence of it? As stated above, it’s trivial to test. Surely if Brand X was doing this, there’d already be blog posts, youtube videos, HN posts, etc. about it?
And what exactly would they use that particular access path for ?
I could see a threat if the TV had access to the internet and could establish a TLS tunnel or similar from the mothership, and execute commands on my LAN (or IoT network as it stands), and report back. That could establish a command & control channel that could potentially orchestrate an attack on my infrastructure via the TV.
However, reporting that "network X exists and has these devices" over a different network complicates things a fair bit. In theory they could still use the TV as a command and control platform, but it would have to switch networks between my closed network and the open network in order to execute commands and report results. Not saying it's impossible, just very unlikely.
Besides, the TVs are not alone in being cut off from the internet. I have two IoT networks, one for trusted devices (AppleTVs, Sonos, and the likes), and one for untrusted devices like TVs. They run on different VLANs, and anything on the untrusted IoT network can pretty much only talk to itself (client isolation) and the gateway, and there's no internet and no open ports to any other VLAN.
> And what exactly would they use that particular access path for ?
Uploading the weeks, months, or years of locally-stored activity [0] data? Text compresses really well and local storage used to be very cheap.
[0] ...mic voice transcription, how often you use the thing, for how long, and a best guess (because of lack of time sync) at when, "automated content detection" logs [1], names of files you've fed to the thing, -if equipped with a camera- number of people in the room and interesting information about them, etc, etc, etc...
[1] ...assuming that that can be done with data loaded from the factory, which I kinda doubt...
Two things:
1) What I called "automated content detection" is apparently called "automated content recognition", abbreviated as "ACR".
2) That weeks, months, or years of locally-stored activity I mentioned can also contain historical ACR records. Given that the audio and video of what's being displayed on the screen is "fingerprinted", those fingerprints can be saved just like everything else picked up by the "TV" and uploaded whenever the thing next has Internet connectivity. The "TV" manufacturer will lose the "what are they doing right now?" aspect of the feature, but the "what have they been doing?" aspect of the feature will work just fine.
Directly related is this section of this Gamers Nexus investigation, but the entire video seems to be worth watching if you're not rather familiar with the topic: <https://youtube.com/watch?v=6IFVTcM28KA&t=26m47s>
That's great that you know how to do that, but LG and others know that also. They don't care that a miniscule amount of ppl can do it, they care about the 99.9999% that don't. Thid should be dealt with legislation and very high fees, sufficient to discourage anyone to do it.
Unfortunately, from LG's surveillance capitalism point of view, the 0.001% of LG owners that can even think about doing that isn't even a drop in the bucket. They don't care about any one individual, and the vast majority of individuals don't care or understand what LG is doing as long as they can watch TV.
It's only a matter of time before another Cambridge Analytica situation pops up, except with better tools and vastly more data. Or maybe something we can't even imagine yet enabled by simply re-purposing ad-tech into something political and malevolent? Some people will be wise to it, of course, but if enough are caught up in it, it won't matter, we all lose as a whole.
Congratulations but I also dislike this type of comment because that is not a solution, a workaround that doesn't happen for 99% of the population.
Soon you won't be able to IoT network or block these devices as they begin to partner with Amazon and the likes that sell Internet for near-by IoT devices. Then your only option then is physically removing / de soldering radios from the board.
Laws needed, like yesterday.
For now, setting up an IoT network is pretty much best practice, and I'd wager the average Hacker News reader both has the necessary equipment and skills to do it. That may not always be the case.
Assuming they install some 5G modem in the device, which is pretty much dirt cheap these days (our local water utility uses 5G for meter readings, and the cost per meter is something like $1/year), there's literally nothing short of a faraday cage you can do.
The can report on what you watch freely, and only consumer laws can stop them. However, without a wifi connection they can't snoop on your local network, and they probably can't connect the data to you, assuming you don't register the TV for those 3 months of added warranty or whatever they try to get you to register.
I tend to avoid devices that are built to snoop on you, so no Amazon Alexa, no Google Home, no Apple HomePod. Everything I have utilizes local control via Home Assistant, and most of it is actively blocked in the firewall from accessing the internet. It's not hard to implement, and doesn't require a master of IT, but it does remove a lot of the convenience, which I guess is the reason people don't do it.
Blocking DNS doesn't do much if the device isn't resolving hostnames and just pushes data to a bunch of preconfigured IPs tho...
If you're streaming via AppleTV, why do you need to give the TV itself access to the network?
I use Home Assistant to turn on/off the TV via automations, sensors, etc.
I could possibly do it via HDMI CEC, but I have a couple of Sony Bravia TVs that more often than not completely ignores that, so I prefer having control over assuming it happens.
You can do on/off using an IR blaster (broadlink integration with discrete on/off codes). It’s when you want to read volume etc things get trickier
I have an automation that turns on amplifier only when using certain inputs, not just when the TV is turned on. I can easily imagine people would also configure their amps to use different input depending on TV input.
Put the tv on a zigbee/matter plug and connect that for the power. (Just be mindful that some TVs need to condition their screens and they will do that when turned “off”, typically during the night. So it you do a hard power off you will need to perform it manually. LG calls it OLED Care iirc.)
Yeah CEC is a bit tricky sometimes. How about auto-off from the TV itself and then a timer for a HA controlled outlet to turn off power after that using automation (i.e., when the streaming device is off for a x minutes)
There is sadly no hdmi CEC support on Most GPUs for pcs. So when you want your tv to turn on and off with your pc it is only possible with the tv being reachable from your pc via ip.
I believe LG doesn’t advertise such an api via Bluetooth
You can get USB controlled CEC injectors for HDMI.
https://www.pulse-eight.com/p/104/usb-hdmi-cec-adapter
For a 4K120Hz TV I'd be worried about this adding signal integrity issues - "all versions of HDMI®, including HDMI® 2.0a" doesn't inspire confidence.
My understanding is that CEC can be received on any alive interface, not just the active.
Yes but you will lose 120 FPS/VRR. So for high end TVs not really ideal.
HDMI breakout and a esp32 module flashed with esphome is another option. The tv most likely doesn’t care that the port that sent on/off command is not the same port the video signal is coming from..
The tv does care which port it came from, since it automatically switches to the one which made the request.
One could build a IR emitter but you need soldering skills for that or buy a usb one which cost north of 30€ + shipping.